Apple to fix FaceTime bug that allows eavesdropping

Apple has disabled a group-chat function in FaceTime after users said a software bug could let callers activate another person's microphone remotely.

News 12 Staff

Jan 29, 2019, 2:48 PM

Updated 1,914 days ago

Share:

Apple to fix FaceTime bug that allows eavesdropping
By MATT O'BRIEN and CARLO PIOVANO
Associated Press
Apple has disabled a group-chat function in FaceTime after users said a software bug could let callers activate another person's microphone remotely.
With the bug, a FaceTime user calling another iPhone, iPad or Mac computer could hear audio - even if the receiver did not accept the call. The bug is triggered when callers add themselves to the same call to launch a group chat. That makes FaceTime think the receiver had accepted the chat.
The bug, demonstrated through videos online , comes as an embarrassment for a company that is trying to distinguish itself by stressing its commitment to users' privacy.
"This is a big hit to their brand," said Dave Kennedy, CEO of Ohio-based security firm TrustedSec. "There's been a long period of time people could have used that to eavesdrop. These things definitely should be caught prior to ever being released."
There is no longer a danger from this particular bug as Apple disabled group chats, while regular, one-on-one FaceTime remains available.
NBC News and The Wall Street Journal reported Tuesday that the family of a 14-year-old high school student in Tucson, Arizona, tried to inform Apple about the bug more than a week before it became widely known to the public. The boy, Grant Thompson, said he discovered it by accident while calling friends to play the game "Fortnite."
It's hard to know if anyone exploited the bug maliciously, said Erka Koivunen, chief information security officer for Finnish company F-Secure. He said it would have been hard to use the bug to spy on someone, as the phone would ring first - and it's easy to identify who called.
Apple said Tuesday that a fix will come in a software update later this week. Apple declined to say when it learned about the problem. The company also wouldn't say if it has logs that could show if anyone took advantage of the bug before it became publicly known this week.
Kennedy commended Apple's quick response this week following reports of the bug by tech blogs. He predicted the reputational dent could soon be forgotten if it doesn't become part of a pattern.
"All bugs are obvious in retrospect," said Eva Galperin, director of cybersecurity at the Electronic Frontier Foundation. "The truth is bugs are subtle, code is complicated and sometimes things get through."
Galperin said Apple should develop a better process for fielding reports about potential security flaws. She said the 14-year-old's discovery of the problem "just tells us a lot about reporting security bugs depends on knowing the right person."
Apple had introduced the 32-person video conferencing feature in October for iPhones, iPads and Macs. Regular FaceTime calls aren't affected unless the caller turns it into a group chat.
Word of the bug came as Apple reported that profit for the last three months of 2018 dipped slightly to $20 billion while revenue fell 5 percent from the prior year to $84 billion. Earlier this month, Apple said that demand for iPhones was waning and that its earnings for the final quarter of 2018 would be below its own forecasts - a rare downgrade from the company.
Copyright 2019 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


More from News 12
1:02
MTA pushes back start date of congestion pricing two weeks to June 30

MTA pushes back start date of congestion pricing two weeks to June 30

2:10
Temperatures dip overnight; Weekend to feature sun and clouds with some light rain

Temperatures dip overnight; Weekend to feature sun and clouds with some light rain

1:43
Police: 2 people injured when tractor-trailer crashes into Cedar Grove pharmacy

Police: 2 people injured when tractor-trailer crashes into Cedar Grove pharmacy

1:53
Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

3:03
Rutgers students remain on alert amid uptick of incidents near New Brunswick campus as 'Rutgers Day' nears

Rutgers students remain on alert amid uptick of incidents near New Brunswick campus as 'Rutgers Day' nears

2:25
Middletown street renamed in honor of iconic New Jersey brothers Stevie and Billy Van Zandt

Middletown street renamed in honor of iconic New Jersey brothers Stevie and Billy Van Zandt

0:25
Services announced for US Rep. Donald Payne, Jr. who died at 65

Services announced for US Rep. Donald Payne, Jr. who died at 65

1:08
New Jersey man says his business and family are at risk if TikTok app is banned

New Jersey man says his business and family are at risk if TikTok app is banned

1:09
Workers call out Gov. Murphy for saying there are 2 sides to casino smoking ban proposal

Workers call out Gov. Murphy for saying there are 2 sides to casino smoking ban proposal

0:31
Police: Former Giants lineman Korey Cunningham, 28, found dead in Clifton home

Police: Former Giants lineman Korey Cunningham, 28, found dead in Clifton home

1:21
SUV crashes through Dunkin' in Old Bridge

SUV crashes through Dunkin' in Old Bridge

0:23
North Wildwood approved for emergency beach replenishment

North Wildwood approved for emergency beach replenishment

0:52
Clothesline Project raises awareness of sexual assault survivors

Clothesline Project raises awareness of sexual assault survivors

0:42
Police: 3 women accused of stealing nearly $600 worth of merchandise from Target

Police: 3 women accused of stealing nearly $600 worth of merchandise from Target

2:17
South Brunswick implements plan to prevent fatal crashes

South Brunswick implements plan to prevent fatal crashes

2:28
Main Street New Jersey: Showcasing the best of North Brunswick

Main Street New Jersey: Showcasing the best of North Brunswick

0:28
Former Carteret middle school teacher accused of sexually assaulting student

Former Carteret middle school teacher accused of sexually assaulting student

0:42
Former NJ national guardsman who set off large FBI manhunt pleads guilty to capitol riot charges

Former NJ national guardsman who set off large FBI manhunt pleads guilty to capitol riot charges

0:33
Somerville man indicted in murder of high school classmate

Somerville man indicted in murder of high school classmate

0:27
Police: Bronx man beaten, stabbed at Showboat Resort Atlantic City; 1 arrested

Police: Bronx man beaten, stabbed at Showboat Resort Atlantic City; 1 arrested